The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A set of 38 security vulnerabilities has been uncovered in wireless industrial internet of things (IIoT) devices from four different vendors that could pose a …
Businesses have been urged to patch the two-year-old vulnerability amidst heightened ransomware threats. "The group has accelerated operations in recent months…
The Gootkit malware is prominently going after healthcare and finance organizations in the U.S., U.K., and Australia, according to new findings from Cybereason…
The OpenSSL Project has released fixes to address several security flaws, including a high-severity bug in the open source encryption toolkit that could potent…
Multiple unpatched security flaws have been disclosed in open source and freemium Document Management System (DMS) offerings from four vendors LogicalDOC, Maya…
Researchers have warned users about a serious zero-day vulnerability in the GoAnywhere MFT software. Exploiting…Emergency Patch Released For GoAnywhere MFT Zer…
Researchers found two security vulnerabilities in the ImageMagick tool that could trigger denial of service…ImageMagick Vulnerabilities Could Allow DoS, Inform…
Threat actors are leveraging known flaws in Sunlogin software to deploy the Sliver command-and-control (C2) framework for carrying out post-exploitation activi…
The Clop ransomware gang is now also using a malware variant that explicitly targets Linux servers, but a flaw in the encryption scheme has allowed victims to …
The first-ever Linux variant of the Clop ransomware has been detected in the wild, but with a faulty encryption algorithm that has made it possible to reverse …
VMware on Monday said it found no evidence that threat actors are leveraging an unknown security flaw, i.e., a zero-day, in its software as part of anongoing r…
The maintainers of OpenSSH have released OpenSSH 9.2 to address a number of security bugs, including a memory safety vulnerability in the OpenSSH server (sshd)…
VMware ESXi hypervisors are the target of a new wave of attacks designed to deploy ransomware on compromised systems."These attack campaigns appear to exploit …
Two new security weaknesses discovered in several electric vehicle (EV) charging systems could be exploited to remotely shut down charging stations and even ex…
Atlassian has released fixes to resolve a critical security flaw in Jira Service Management Server and Data Center that could be abused by an attacker to pass …
Atlassian has released fixes to resolve a critical security flaw in Jira Service Management Server and Data Center that could be abused by an attacker to pass …
F5 has warned of a high-severity flaw impacting BIG-IP appliances that could lead to denial-of-service (DoS) or arbitrary code execution.The issue is rooted in…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on February 2addedtwo security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, cit…
Last week I wrote about Linux developers evaluating a new "DOITM" security mitigation for the latest Intel CPUs . While the cost for now of engaging the Data O…
Researchers have devised a ChromeOS exploit that unlocks enterprise-managed Chromebooks. While Google is addressing the…New SH1MMER ChromeOS Exploit Jailbreaks…
Two more supply chain security flaws have been disclosed in AMI MegaRAC Baseboard Management Controller (BMC) software, nearly two months afterthree security v…
Taiwanese company QNAP has released updates to remediate a critical security flaw affecting its network-attached storage (NAS) devices that could lead to arbit…
A researcher won a hefty bounty for reporting a severe two-factor authentication (2FA) bypass bug…Serious 2FA Bypass Vulnerability Affected Facebook And Instag…
Open source security automation is a critical aspect of modern cybersecurity. It involves the use of open source tools and technologies to automate various sec…